
Undocumented Copilot prompt bypass enables data exfiltration via malicious link
Varonis researchers demonstrated a vulnerability in Microsoft 365 Copilot Enterprise: an undocumented URL parameter (?autorun=1) could auto‑execute prompts without user consent when a user clicked a crafted link, allowing exfiltration of passwords and other sensitive data. Microsoft mitigated the issue by disabling the ?q= prompt injection and later rolled out broader fixes, illustrating how guardrails for LLMs can fail and that prompt injections (including memory‑poisoning attacks) remain a risk. Users should be cautious with untrusted links and limit AI app access.













